Maxinames
Back to Policies & Legal
Policies & LegalUpdated

GDPR and Your Data

Maxinames as controller and processor, your DPA, data hosting locations, and how we help with subject access and breach reporting.

The General Data Protection Regulation (GDPR) is the EU/UK law that governs how personal data is handled. This article explains how Maxinames complies, and how the GDPR applies to your data when it sits on our infrastructure.

Our role

For your account data (your name, billing details, service configuration), Maxinames is the data controller — we decide what we do with it. Our handling is documented in the Privacy Policy.

For data your visitors submit to your site hosted on our servers (form submissions, customer accounts, e-commerce orders), Maxinames is the data processor — you are the controller, and we process the data on your behalf.

Your obligations as controller

If your site collects personal data from EU/UK visitors, the GDPR requires you to:

  • Have a privacy policy that explains what you collect, why, and how visitors can exercise their rights.
  • Get valid consent for cookies and tracking that go beyond what is strictly necessary.
  • Honour subject access requests within 30 days.
  • Notify the relevant authority of personal data breaches within 72 hours.

Data processing agreement (DPA)

EU-based customers and customers handling EU data should request our DPA — a signed agreement spelling out our role as processor. Email privacy@maxinames.com and we will send the current version for signature.

Where your data is hosted

Hosting infrastructure is in the regions selected at signup. Account and billing data resides in our central systems, which are hosted in EU datacentres. Where data leaves the EU/UK, it is covered by Standard Contractual Clauses (SCCs).

Subject access requests on your behalf

If a visitor of your hosted site asks for their data and you need our help locating it (for example, in server logs), open a support ticket and we will help within the GDPR-mandated 30-day window.

Data breach handling

If we detect a security incident affecting personal data, we notify affected customers without undue delay, with enough information for you to meet your own 72-hour reporting obligation if applicable.

Useful links

Still need help?

Our support team replies to tickets around the clock.